Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activityremote-access-implantfinancial-sector-threatphishing-campaign-intelligence

ClickFix Campaigns Deliver Modular RATs, Banking Trojans, and macOS Stealers

Updated 2mo agoFirst seen Apr 11, 20267 sources

Researchers reported multiple ClickFix campaigns using fake CAPTCHA or reCAPTCHA prompts to trick users into manually running malicious commands, with payloads tailored by platform and victim profile. On Windows, one campaign delivered a modular NodeJS-based RAT and infostealer through a malicious MSI installer, loading key capabilities only in memory after command-and-control was established and using gRPC over Tor for persistent communications. An operational security failure exposed the malware’s backend protocol definitions and admin panel API, revealing a malware-as-a-service operation with multi-operator support, Telegram alerts, automation rules, and cryptocurrency wallet tracking. The malware also fingerprinted victims extensively and established persistence through the Windows Run registry key as LogicOptimizer.

A separate ClickFix chain attributed with high confidence to Grandoreiro targeted users of eight Brazilian banks by luring victims through a fake reCAPTCHA page and launching a malicious PowerShell sequence that sideloaded a Delphi banking trojan with legitimate GoToMeeting and Nero binaries. The malware deployed banking overlays, intercepted PIX QR-code payments, added Microsoft Defender exclusions, and stole credentials, device information, signatures, and payment confirmation codes. Netskope also documented a macOS variant that used AppleScript and a persistent fake password dialog to harvest Keychain data, browser cookies, saved credentials, extension storage, and cryptocurrency wallet data; the theft of live session cookies can enable attackers to bypass MFA by hijacking authenticated sessions.

Share:
ClickFix Campaigns Deliver Modular RATs, Banking Trojans, and macOS Stealers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
Apr 30, 20262mo ago

Huntress details BackgroundFix ClickFix chain delivering CastleLoader

Huntress reported a ClickFix-style campaign in which victims searching for background-removal tools were lured to malicious 'BackgroundFix' sites that copied a command for execution via the Windows Run dialog. The chain abused finger.exe to fetch a batch payload, downloaded Python-based stages, and ultimately deployed CastleLoader, which was observed delivering NetSupport RAT and an in-memory stealer dubbed CastleStealer.

ClickFix Removes Your Background but Leaves the Malware | Huntress
Apr 20, 20262mo ago

Apple adds Terminal protections aimed at ClickFix-style lures

Netskope noted that macOS Tahoe 26.4 and macOS Sequoia introduced Terminal warnings intended to disrupt ClickFix social-engineering attacks that rely on users manually pasting malicious commands.

Netskope documents macOS ClickFix stealer variant

Netskope described a cross-platform ClickFix campaign delivering an AppleScript-based infostealer to macOS users through a fake CAPTCHA flow and repeated password prompts. The stealer collected Keychain data, browser credentials, cookies, extension storage, and cryptocurrency wallet data before exfiltrating it to 172.94.9.250.

Apr 8, 20263mo ago

Grandoreiro campaign targets eight Brazilian banks via ClickFix chain

Researchers observed a Grandoreiro-family banking trojan campaign using a fake reCAPTCHA ClickFix/ClearFake-style lure on canalmodup.com to trick victims into running malicious PowerShell. The operation used GoToMeeting and Nero WiFi+Transfer DLL sideloading and targeted eight major Brazilian banks with overlays and PIX QR-code interception.

Apr 6, 20263mo ago

Netskope exposes modular Windows RAT and leaked MaaS admin panel

Netskope Threat Labs reported a ClickFix campaign delivering a NodeJS-based modular Windows RAT/infostealer through a malicious MSI installer. The malware used gRPC over Tor, in-memory modules, and persistence via the LogicOptimizer Run key, while an operational security failure exposed protocol definitions and an admin panel API showing a mature multi-operator malware-as-a-service platform.

Mar 15, 20263mo ago

Breakglass links 333+ ClickFix infections to abused signed NetSupport RAT

Breakglass reported that attackers were abusing a legitimately EV-signed NetSupport Manager v14.12 binary as a RAT in two active delivery chains, including fake Cloudflare Turnstile/reCAPTCHA ClickFix pages that tricked users into pasting PowerShell. The report tied the activity to likely Russian-speaking MaaS operators, noted the infrastructure was still active, and published IOCs, hashes, domains, IPs, and detection guidance.

Signed, Sealed, Delivered: How a Legitimately-Signed NetSupport Binary Became a Weapon Across 333+ ClickFix Infections - Breakglass Intelligence - Breakglass Intelligence
Mar 12, 20263mo ago

Breakglass reports ClickFix campaign weaponizing NetSupport RAT against Italian users

Breakglass disclosed a campaign distributing weaponized NetSupport Manager v14.10 via fake CAPTCHA or verification pages that tricked victims into pasting a PowerShell command. The operation targeted Italian users through spam emails and used signed NetSupport binaries with malicious config and license files, alongside multiple landing, delivery, and C2 domains.

Campaign #39: NetSupport RAT Weaponized via ClickFix Social Engineering at Scale - Breakglass Intelligence - Breakglass Intelligence
Mar 7, 20264mo ago

Breakglass documents SectopRAT ClickFix campaign using 42 .in.net domains

Breakglass reported that from March 7 to March 9, 2026, attackers ran a ClickFix campaign that used 42 newly registered .in.net parent domains and at least 156 subdomains to trick victims into pasting a PowerShell command from fake Google verification pages. The infection chain deployed SectopRAT through a five-stage loader with layered encryption and Donut shellcode, and the infrastructure showed signs of bulk automation and links to the broader ACRStealer/Arechclient2 ecosystem.

ClickFix Drops SectopRAT Through Three Encryption Layers: 42 Domains, 156 Subdomains, and a 48-Hour Infrastructure Blitz on .in.net - Breakglass Intelligence - Breakglass Intelligence
Dec 1, 20257mo ago

Certificates issued for Grandoreiro campaign before activation

Breakglass observed that certificates tied to the canalmodup.com infrastructure were issued before the campaign became active, indicating preparation in advance of operations.

canalmodup.com registered for Grandoreiro campaign infrastructure

Breakglass reported that the domain canalmodup.com, later used in a ClickFix-style Grandoreiro campaign, was registered in December 2025 as part of pre-staged attacker infrastructure.

Dec 1, 20242y ago

ClickFix social-engineering technique first observed

Netskope said the ClickFix technique was first seen in late 2024, using fake verification prompts to trick users into manually pasting malicious commands into Terminal or Windows Run dialogs.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

104 LINKEDOpen in app
Vulnerabilities
1 linked
Threat actors
1 linked
Affected products
30 linked
WindowsPythonCloudflareFirefoxNginxDash CoreRemote Desktop ProtocolWindows InstallerTelegramApache Http ServerBitwarden1passwordDashlanePowershellBrave BrowserAuthy.Net FrameworkThunderbirdLedger LiveExpressArcTrust WalletOperaMetamaskMacos TahoeMacos SequoiaGrpcNode.JsWindows PowershellMicrosoft Defender
Organizations
58 linked
GoogleNetsupportGitHubCloudflarePython Software FoundationValidinMicrosoft CorporationHuntressBreakglass IntelligenceGlobalSignKasperskyNetskopeBroadcomNICENICTrend MicroThe Tor ProjectMalwarebytesBanco do BrasilBanco BradescoBanco SantanderPalo Alto NetworksMcafeeF-SecureEsetInternational Business MachinesAvastCrowdStrikeReversingLabsItaú UnibancoTelegramSentinelOneDigiCertLogmeinSophosBitdefenderSicoobSicrediCaixa Econômica Federalabuse.chLet's EncryptData Campus LimitedProton66 OOOGAS TecnologiaQWINS LTDHello Internet CorpOmegatech LTDGLOBAL CONNECTIVITY SOLUTIONS LLPTopazRegister S.p.A.UnicredNero AGEVEO S.A.DEDIK ServicesPDR Ltd. d/b/a PublicDomainRegistry.comWebNic.ccSkayvin ISPCentralNicMivoCloud SRL
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

ClickFix Campaigns Deliver Modular RATs, Banking Trojans, and macOS Stealers | Mallory